[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1082902: bookworm-pu: package nghttp2/1.52.0-1+deb12u2



On Sat, Sep 28, 2024 at 02:38:29AM +0300, Adrian Bunk wrote:
> Package: release.debian.org
> Severity: normal
> Tags: bookworm
> User: release.debian.org@packages.debian.org
> Usertags: pu
> X-Debbugs-Cc: security@debian.org, Tomasz Buchert <tomasz@debian.org>
> 
>   * CVE-2024-28182: unbounded number of HTTP/2 CONTINUATION frames DoS
>     (Closes: #1068415)
>   * nghttp2_option_set_stream_reset_rate_limit was added in
>     1.52.0-1+deb12u1, add to debian/libnghttp2-14.symbols
> 
> Tagged moreinfo, as question to the security team whether they want
> this in -pu or as DSA.

pu is fine, thanks!

Cheers,
        Moritz


Reply to: